Create and store a token
- Sign in to Tilde as an organization administrator.
- Select the organization and open Settings → Organization → Proxy tokens.
- Choose Create token, enter an application/environment name, and select capabilities.
- Set an optional expiry. Register exact return URLs if you enable managed linking.
- Copy the one-time secret into your server’s secret store.
Choose capabilities
Enable only the capabilities the application uses. An application that provisions
users and teams and offers account linking needs all four. You can use separate
credentials for runtime traffic and provisioning if they run in separate services.
Provisioning requests use the unbound application client. Runtime requests include
an acting identity. The SDK browser proxy does not expose provisioning, token
management, billing, account-link completion, or account administration.
Mount the server proxy
The SDK accepts standard FetchRequest and Response objects. In a Next.js App
Router application, mount one handler for all supported methods:
app/api/tilde/[...path]/route.ts
resolveApplicationSession(request) is your server adapter. It verifies your
provider’s session, checks your local lifecycle state, and loads the persisted
identity/team mapping. Return null when unauthenticated, or:
allowedTeamIds from browser input. For a one-team-per-user app,
return only the mapped initial team. For collaboration, load currently permitted
teams from trusted membership data. Tilde independently validates membership.
The proxy replaces inbound authentication and delegation headers, fixes the
upstream origin, checks team selection, and preserves streaming, uploads,
cancellation, and response status. Mutations require the browser’s same-origin
Origin header. Upstream credentials, cookies, and redirect locations are not
forwarded to the browser.
Wire format
Server-to-server runtime calls carry:/api/v1/team/{team_id}/.... Keep identity delegation in its
explicit header rather than adding it to resource request bodies. Do not combine
proxy credentials with a login cookie, bearer token, or API key. Tilde rejects
conflicting credentials and tenant routing.
An organization token has a broader compromise scope than a single user’s
credential: a holder with runtime delegation can select identities across that
organization. Your proxy must authenticate every request and constrain the team
and identity, while Tilde enforces the final tenant and resource boundaries.
Manage and rotate
The table shows name, masked identifier, capabilities, creation and expiry, last use, and status. Administrators can rename, create a replacement, or revoke a token. Replacement creation leaves the old token active until explicitly revoked:- Create a replacement and store its new secret.
- Deploy the new configuration and verify application requests.
- Revoke the old token and confirm it no longer authorizes requests.